OASIS Open Mailing List Archives  ·  All Lists  ·  xacml  ·  2004-05

xacml — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

Re: Fw: undefined


 MHonArc v2.5.0b2 -->


















xacml message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: Fw: undefined


No, with my proposal, the senior role only needs to know the
junior roles it *immediately* includes.  It does not need to know
the even more junior roles that those include, since the normal
XACML PDP processing rules follow nested roles.

It is much easier (and more realistic) to manage what *immediate*
junior roles a senior role should include that to try to manage
the *entire chain* of senior roles that include each junior role.
Having more senior roles control which junior roles they include
fits the hierarchical model better than having junior roles
control the entire chain of senior roles that include them.

Anne

On 21 May, Aleksey Studnev writes: Re: Fw: undefined
 > From: Aleksey Studnev <[email protected]>
 > To: [email protected]
 > Cc: XACML TC <[email protected]>
 > Subject: Re: Fw: undefined
 > Date: Fri, 21 May 2004 18:02:04 +0400
 > 
 > Anne,
 > 
 > your idea is that requirement to senior role to know all junior roles is 
 > better than 
 > junior role knowing all senior roles?
 > 
 > Aleksey
 > 
 > 
 > 
 > 
 > Anne Anderson <[email protected]> 
 > 05/21/2004 05:48 PM
 > Please respond to
 > [email protected]
 > 
 > 
 > To
 > Aleksey Studnev <[email protected]>
 > cc
 > XACML TC <[email protected]>
 > Subject
 > Re: Fw: undefined
 > 
 > 
 > 
 > 
 > 
 > 
 > Aleksey,
 > 
 > The proposal you describe requires the administrator (or the
 > policy generation system) of each junior role to "know" each
 > senior role that includes it.  That is not scalable to large
 > distributed systems of roles.  To use your words, "This opens
 > another door for inconsistent policies where these statements are
 > wrongly expressed."
 > 
 > No tool or administrator can know which senior roles include each
 > junior role unless the tool is keeping a global index of all the
 > policies that is updated every time a policy is changed.
 > 
 > Having the tool manage only a single <PolicySet> at a time seems
 > to me to be a big plus in simplicity and scalability.
 > 
 > Anne
 > 
 > On 20 May, Aleksey Studnev writes: Fw: undefined
 >  > From: Aleksey Studnev <[email protected]>
 >  > To: [email protected]
 >  > Subject: Fw: undefined
 >  > Date: Thu, 20 May 2004 23:21:54 +0400
 >  > 
 >  > Anne,
 >  > 
 >  > sorry for mistake, i of course reversed the hierarchy. It should look 
 > like:
 >  > 
 >  > <PolicySet>
 >  > <Policy>
 >  >  <Target>
 >  >   ResourceAttributeDesignator "role" = AttributeValue "Manager"
 >  >  </Target>
 >  >  <Rule Effect="Permit">
 >  >   <Target>
 >  >    SubjectAttributeDesignator 
 > "urn:oasis:names:xacml:2.0:subject:subject-id" = AttributeValue "Aleksey"
 >  >    ActionAttributeDesignator "action-id" = AttributeValue "enable"
 >  >   </Target>
 >  >  </Rule>
 >  > </Policy>
 >  > 
 >  > <Policy>
 >  >  <Target>
 >  >   ResourceAttributeDesignator "role" = AttributeValue "Employee"
 >  >  </Target>
 >  >  <Rule Effect="Permit">
 >  >   <Target>
 >  >    SubjectAttributeDesignator 
 > "urn:oasis:names:xacml:2.0:subject:subject-id" = AttributeValue "Kill 
 > Bill"
 >  >    ActionAttributeDesignator "action-id" = AttributeValue "enable"
 >  >   </Target>
 >  >  </Rule>
 >  >  <Rule Effect="Permit">
 >  >   <Target>
 >  >    SubjectAttributeDesignator "role-id" == AttributeValue "Manager"
 >  >    ActionAttributeDesignator "action-id" == AttributeValue "grant"
 >  >   </Target>
 >  >  </Rule>
 >  > </Policy>
 >  > 
 >  > </PolicySet>
 >  > 
 >  > Here Aleksey is Manager and "Kill Bill" is Employee.
 >  > 
 >  > Regards,
 >  > 
 >  > Aleksey
 >  > 
 >  > 
 >  > Anne,
 >  > 
 >  > lets take that old example with Aleksey Manager. What i propose is to 
 > roles assignment policy like:
 >  > 
 >  > 
 >  > <Policy>
 >  >  <Target>
 >  >   ResourceAttributeDesignator "role" = AttributeValue "Manager"
 >  >  </Target>
 >  >  <Rule Effect="Permit">
 >  >   <Target>
 >  >    SubjectAttributeDesignator 
 > "urn:oasis:names:xacml:2.0:subject:subject-id" = AttributeValue "Aleksey"
 >  >    ActionAttributeDesignator "action-id" = AttributeValue "enable"
 >  >   </Target>
 >  >  </Rule>
 >  >  <Rule Effect="Permit">
 >  >   <Target>
 >  >    SubjectAttributeDesignator "role-id" == AttributeValue "Employee"
 >  >    ActionAttributeDesignator "action-id" == AttributeValue "grant"
 >  >   </Target>
 >  >  </Rule>
 >  > </Policy>
 >  > 
 >  > So Aleksey will be granted role attributes "Employee" and "Manager".
 >  > Role policies remains "as is".
 >  > Reference ( to "Employee" Permission Policy Set) to be removed from 
 > "Manager" permission policy set.
 >  > 
 >  > Regards,
 >  > 
 >  > Aleksey
 > 
 > -- 
 > Anne H. Anderson             Email: [email protected]
 > Sun Microsystems Laboratories
 > 1 Network Drive,UBUR02-311     Tel: 781/442-0928
 > Burlington, MA 01803-0902 USA  Fax: 781/442-1692
 > 
 > 
 > 
 > <br><font size=2 face="sans-serif">Anne,</font>
 > <br>
 > <br><font size=2 face="sans-serif">your idea is that requirement to senior
 > role to know all junior roles is better than </font>
 > <br><font size=2 face="sans-serif">junior role knowing all senior roles?</font>
 > <br>
 > <br><font size=2 face="sans-serif">Aleksey</font>
 > <br>
 > <br>
 > <br>
 > <br>
 > <table width=100%>
 > <tr valign=top>
 > <td><font size=1 face="sans-serif"><b>Anne Anderson &lt;[email protected]&gt;</b>
 > </font>
 > <p><font size=1 face="sans-serif">05/21/2004 05:48 PM</font>
 > <table border>
 > <tr valign=top>
 > <td bgcolor=white>
 > <div align=center><font size=1 face="sans-serif">Please respond to<br>
 > [email protected]</font></div></table>
 > <br>
 > <td>
 > <table width=100%>
 > <tr>
 > <td>
 > <div align=right><font size=1 face="sans-serif">To</font></div>
 > <td valign=top><font size=1 face="sans-serif">Aleksey Studnev &lt;[email protected]&gt;</font>
 > <tr>
 > <td>
 > <div align=right><font size=1 face="sans-serif">cc</font></div>
 > <td valign=top><font size=1 face="sans-serif">XACML TC &lt;[email protected]&gt;</font>
 > <tr>
 > <td>
 > <div align=right><font size=1 face="sans-serif">Subject</font></div>
 > <td valign=top><font size=1 face="sans-serif">Re: Fw: undefined</font></table>
 > <br>
 > <table>
 > <tr valign=top>
 > <td>
 > <td></table>
 > <br></table>
 > <br>
 > <br>
 > <br><font size=2><tt>Aleksey,<br>
 > <br>
 > The proposal you describe requires the administrator (or the<br>
 > policy generation system) of each junior role to &quot;know&quot; each<br>
 > senior role that includes it. &nbsp;That is not scalable to large<br>
 > distributed systems of roles. &nbsp;To use your words, &quot;This opens<br>
 > another door for inconsistent policies where these statements are<br>
 > wrongly expressed.&quot;<br>
 > <br>
 > No tool or administrator can know which senior roles include each<br>
 > junior role unless the tool is keeping a global index of all the<br>
 > policies that is updated every time a policy is changed.<br>
 > <br>
 > Having the tool manage only a single &lt;PolicySet&gt; at a time seems<br>
 > to me to be a big plus in simplicity and scalability.<br>
 > <br>
 > Anne<br>
 > <br>
 > On 20 May, Aleksey Studnev writes: Fw: undefined<br>
 >  &gt; From: Aleksey Studnev &lt;[email protected]&gt;<br>
 >  &gt; To: [email protected]<br>
 >  &gt; Subject: Fw: undefined<br>
 >  &gt; Date: Thu, 20 May 2004 23:21:54 +0400<br>
 >  &gt; <br>
 >  &gt; Anne,<br>
 >  &gt; <br>
 >  &gt; sorry for mistake, i of course reversed the hierarchy. It should
 > look like:<br>
 >  &gt; <br>
 >  &gt; &lt;PolicySet&gt;<br>
 >  &gt; &lt;Policy&gt;<br>
 >  &gt; &nbsp;&lt;Target&gt;<br>
 >  &gt; &nbsp; ResourceAttributeDesignator &quot;role&quot; = AttributeValue
 > &quot;Manager&quot;<br>
 >  &gt; &nbsp;&lt;/Target&gt;<br>
 >  &gt; &nbsp;&lt;Rule Effect=&quot;Permit&quot;&gt;<br>
 >  &gt; &nbsp; &lt;Target&gt;<br>
 >  &gt; &nbsp; &nbsp;SubjectAttributeDesignator &quot;urn:oasis:names:xacml:2.0:subject:subject-id&quot;
 > = AttributeValue &quot;Aleksey&quot;<br>
 >  &gt; &nbsp; &nbsp;ActionAttributeDesignator &quot;action-id&quot; = AttributeValue
 > &quot;enable&quot;<br>
 >  &gt; &nbsp; &lt;/Target&gt;<br>
 >  &gt; &nbsp;&lt;/Rule&gt;<br>
 >  &gt; &lt;/Policy&gt;<br>
 >  &gt; <br>
 >  &gt; &lt;Policy&gt;<br>
 >  &gt; &nbsp;&lt;Target&gt;<br>
 >  &gt; &nbsp; ResourceAttributeDesignator &quot;role&quot; = AttributeValue
 > &quot;Employee&quot;<br>
 >  &gt; &nbsp;&lt;/Target&gt;<br>
 >  &gt; &nbsp;&lt;Rule Effect=&quot;Permit&quot;&gt;<br>
 >  &gt; &nbsp; &lt;Target&gt;<br>
 >  &gt; &nbsp; &nbsp;SubjectAttributeDesignator &quot;urn:oasis:names:xacml:2.0:subject:subject-id&quot;
 > = AttributeValue &quot;Kill Bill&quot;<br>
 >  &gt; &nbsp; &nbsp;ActionAttributeDesignator &quot;action-id&quot; = AttributeValue
 > &quot;enable&quot;<br>
 >  &gt; &nbsp; &lt;/Target&gt;<br>
 >  &gt; &nbsp;&lt;/Rule&gt;<br>
 >  &gt; &nbsp;&lt;Rule Effect=&quot;Permit&quot;&gt;<br>
 >  &gt; &nbsp; &lt;Target&gt;<br>
 >  &gt; &nbsp; &nbsp;SubjectAttributeDesignator &quot;role-id&quot; == AttributeValue
 > &quot;Manager&quot;<br>
 >  &gt; &nbsp; &nbsp;ActionAttributeDesignator &quot;action-id&quot; == AttributeValue
 > &quot;grant&quot;<br>
 >  &gt; &nbsp; &lt;/Target&gt;<br>
 >  &gt; &nbsp;&lt;/Rule&gt;<br>
 >  &gt; &lt;/Policy&gt;<br>
 >  &gt; <br>
 >  &gt; &lt;/PolicySet&gt;<br>
 >  &gt; <br>
 >  &gt; Here Aleksey is Manager and &quot;Kill Bill&quot; is Employee.<br>
 >  &gt; <br>
 >  &gt; Regards,<br>
 >  &gt; <br>
 >  &gt; Aleksey<br>
 >  &gt; <br>
 >  &gt; <br>
 >  &gt; Anne,<br>
 >  &gt; <br>
 >  &gt; lets take that old example with Aleksey Manager. What i propose is
 > to roles assignment policy like:<br>
 >  &gt; <br>
 >  &gt; <br>
 >  &gt; &lt;Policy&gt;<br>
 >  &gt; &nbsp;&lt;Target&gt;<br>
 >  &gt; &nbsp; ResourceAttributeDesignator &quot;role&quot; = AttributeValue
 > &quot;Manager&quot;<br>
 >  &gt; &nbsp;&lt;/Target&gt;<br>
 >  &gt; &nbsp;&lt;Rule Effect=&quot;Permit&quot;&gt;<br>
 >  &gt; &nbsp; &lt;Target&gt;<br>
 >  &gt; &nbsp; &nbsp;SubjectAttributeDesignator &quot;urn:oasis:names:xacml:2.0:subject:subject-id&quot;
 > = AttributeValue &quot;Aleksey&quot;<br>
 >  &gt; &nbsp; &nbsp;ActionAttributeDesignator &quot;action-id&quot; = AttributeValue
 > &quot;enable&quot;<br>
 >  &gt; &nbsp; &lt;/Target&gt;<br>
 >  &gt; &nbsp;&lt;/Rule&gt;<br>
 >  &gt; &nbsp;&lt;Rule Effect=&quot;Permit&quot;&gt;<br>
 >  &gt; &nbsp; &lt;Target&gt;<br>
 >  &gt; &nbsp; &nbsp;SubjectAttributeDesignator &quot;role-id&quot; == AttributeValue
 > &quot;Employee&quot;<br>
 >  &gt; &nbsp; &nbsp;ActionAttributeDesignator &quot;action-id&quot; == AttributeValue
 > &quot;grant&quot;<br>
 >  &gt; &nbsp; &lt;/Target&gt;<br>
 >  &gt; &nbsp;&lt;/Rule&gt;<br>
 >  &gt; &lt;/Policy&gt;<br>
 >  &gt; <br>
 >  &gt; So Aleksey will be granted role attributes &quot;Employee&quot; and
 > &quot;Manager&quot;.<br>
 >  &gt; Role policies remains &quot;as is&quot;.<br>
 >  &gt; Reference ( to &quot;Employee&quot; Permission Policy Set) to be
 > removed from &quot;Manager&quot; permission policy set.<br>
 >  &gt; <br>
 >  &gt; Regards,<br>
 >  &gt; <br>
 >  &gt; Aleksey<br>
 > <br>
 > -- <br>
 > Anne H. Anderson &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Email: [email protected]<br>
 > Sun Microsystems Laboratories<br>
 > 1 Network Drive,UBUR02-311 &nbsp; &nbsp; Tel: 781/442-0928<br>
 > Burlington, MA 01803-0902 USA &nbsp;Fax: 781/442-1692<br>
 > <br>
 > </tt></font>
 > <br>

-- 
Anne H. Anderson             Email: [email protected]
Sun Microsystems Laboratories
1 Network Drive,UBUR02-311     Tel: 781/442-0928
Burlington, MA 01803-0902 USA  Fax: 781/442-1692



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]



[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]